Moneycontrol PRO
Black Friday Sale
Black Friday Sale
HomeTechnologyHackers attack Chrome extensions, spreading dangerous code to users

Hackers attack Chrome extensions, spreading dangerous code to users

California-based cybersecurity firm Cyberhaven has confirmed that hackers have published a malicious update to its Chrome extensions, exposing over 6,00,000 users to potential data theft. This breach puts Facebook ad users at high risk of account hacking or unknown access

December 30, 2024 / 20:16 IST
Chrome

A sophisticated cyberattack campaign has targeted 16 Chrome extensions to steal sensitive data of Facebook ad users. According to an initial investigation by the cybersecurity firm Cyberhaven, the malicious code was designed to steal sensitive data, including access tokens, user IDs, account information, cookies, and other sensitive data.

Google Chrome extensions attack: Key details

According to a new report by Reuters, security researcher Jaime Blasco has stated that the attack was a random malware injection and not targeting Cyberhaven specifically. Further, he added that VPN and AI extensions containing the same malicious code that was inserted into Cyberhaven were responsible for security breaches for other firms.

Cyberhaven has a prestigious list of customers, using its servers such as Snowflake, Motorola, Canon, Reddit, AmeriHealth, Upstart, and others. The cybersecurity company reported in a blog post that its Chrome extension was hacked on December 24, in an attack targeting logins to certain social media advertising and AI platforms. Other extensions, including ParrotTalks, Uvoice, and VPNCity, and 13 other Chrome extensions were also affected.

However, according to the company, the incident was brief and limited. Only version 24.10.4 of the Cyberhaven Chrome extension was affected, and the malicious code was active for less than a day. Till now, Cyberhaven has declined to comment about how many affected customers it had notified about the breach and assured that only Chrome browsers that auto-updated during the time of the cyberattack were impacted.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Sandip Chakraborty
first published: Dec 30, 2024 08:16 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347